🟠 High — Wysokie podatności CVE (CVSS 7.0–8.9) wymagające pilnego łatania. Znaleziono 200 CVE.

Inne poziomy: 🔴 Critical 🟡 Medium ⚪ Low
CVE-2021-34527 🔴 Łataj teraz KEV
appscloud

A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with …

8.8 CVSS
99.8% EPSS
microsoftexploitrce 2021-07-02
CVE-2017-0144 🔴 Łataj teraz KEV

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 20…

8.8 CVSS
99.2% EPSS
siemensexploitrce 2017-03-17
CVE-2020-0618 🔴 Łataj teraz KEV
appscloud

A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka 'Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability'.

8.8 CVSS
99.0% EPSS
microsoftexploitrce 2020-02-11
CVE-2024-24919 🔴 Łataj teraz KEV

Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades. A Security fix that mitiga…

8.6 CVSS
100.0% EPSS
checkpoint 2024-05-28
CVE-2021-40444 🔴 Łataj teraz KEV
appscloud

Microsoft is investigating reports of a remote code execution vulnerability in MSHTML that affects Microsoft Windows. Microsoft is aware of targeted attacks that attempt to exploit this vulnerability by using specially-c…

8.8 CVSS
97.5% EPSS
microsoftexploitrce 2021-09-15
CVE-2026-34197 🔴 Łataj teraz KEV
apps

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/…

8.8 CVSS
97.2% EPSS
apacherce 2026-04-07
CVE-2024-21893 🔴 Łataj teraz KEV

A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted resou…

8.2 CVSS
100.0% EPSS
ivantissrf 2024-01-31
CVE-2023-46805 🔴 Łataj teraz KEV

An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing control checks.

8.2 CVSS
100.0% EPSS
CVE-2017-12617 🔴 Łataj teraz KEV
appsos

When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to fal…

8.1 CVSS
100.0% EPSS
oracleexploit 2017-10-04
CVE-2017-12615 🔴 Łataj teraz KEV
os

When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a speci…

8.1 CVSS
99.6% EPSS
redhatexploit 2017-09-19
CVE-2021-27065 🔴 Łataj teraz KEV
appscloud

Microsoft Exchange Server Remote Code Execution Vulnerability

7.8 CVSS
99.9% EPSS
microsoftexploitrce 2021-03-03
CVE-2025-8088 🔴 Łataj teraz KEV
appscloud

A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild and was discovered b…

8.8 CVSS
94.5% EPSS
CVE-2022-30190 🔴 Łataj teraz KEV
appscloud

A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run arbitrary code with the pr…

7.8 CVSS
99.4% EPSS
microsoftexploitrce 2022-06-01
CVE-2016-6277 🔴 Łataj teraz KEV
network

NETGEAR R6250 before 1.0.4.6.Beta, R6400 before 1.0.1.18.Beta, R6700 before 1.0.1.14.Beta, R6900, R7000 before 1.0.7.6.Beta, R7100LG before 1.0.0.28.Beta, R7300DST before 1.0.0.46.Beta, R7900 before 1.0.1.8.Beta, R8000 b…

8.8 CVSS
94.3% EPSS
netgearexploit 2016-12-14
CVE-2017-9822 🔴 Łataj teraz KEV

DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka "2017-08 (Critical) Possible remote code execution on DNN sites."

8.8 CVSS
94.3% EPSS
CVE-2012-0158 🔴 Łataj teraz KEV
appscloud

The (1) ListView, (2) ListView2, (3) TreeView, and (4) TreeView2 ActiveX controls in MSCOMCTL.OCX in the Common Controls in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Office 2003 Web Components S…

8.8 CVSS
94.3% EPSS
microsoftrce 2012-04-10
CVE-2014-6332 🔴 Łataj teraz KEV
appscloud

OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows …

8.8 CVSS
94.1% EPSS
microsoftexploitrce 2014-11-11
CVE-2017-0143 🔴 Łataj teraz KEV

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 20…

8.8 CVSS
94.0% EPSS
siemensexploitrce 2017-03-17
CVE-2017-8464 🔴 Łataj teraz KEV
appscloud

Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows loc…

8.8 CVSS
93.9% EPSS
microsoftexploitrce 2017-06-15
CVE-2011-0611 🔴 Łataj teraz KEV

Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.19140; and Authplay.dll (aka AuthPlayLib.bundle) in Adobe Reader 9.x before 9.4.…

8.8 CVSS
93.7% EPSS
adobedosexploit 2011-04-13
CVE-2010-1871 🔴 Łataj teraz KEV

JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, does not properly sanitize inputs for JBoss Expression Language (EL) expressions, which allows remote attackers to exe…

8.8 CVSS
93.6% EPSS
netapp 2010-08-05
CVE-2023-44487 🔴 Łataj teraz KEV
network

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

7.5 CVSS
100.0% EPSS
ciscodosexploit 2023-10-10
CVE-2017-10271 🔴 Łataj teraz KEV
appsos

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitab…

7.5 CVSS
100.0% EPSS
oracleexploit 2017-10-19
CVE-2020-3452 🔴 Łataj teraz KEV
network

A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct directory tra…

7.5 CVSS
100.0% EPSS
CVE-2025-5777 🔴 Łataj teraz KEV

Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server

7.5 CVSS
100.0% EPSS
citrix 2025-06-17
CVE-2019-7481 🔴 Łataj teraz KEV
network

Vulnerability in SonicWall SMA100 allow unauthenticated user to gain read-only access to unauthorized resources. This vulnerablity impacted SMA100 version 9.0.0.3 and earlier.

7.5 CVSS
99.9% EPSS
sonicwall 2019-12-17
CVE-2018-0296 🔴 Łataj teraz KEV
network

A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (Do…

7.5 CVSS
99.9% EPSS
CVE-2009-0927 🔴 Łataj teraz KEV

Stack-based buffer overflow in Adobe Reader and Adobe Acrobat 9 before 9.1, 8 before 8.1.3 , and 7 before 7.1.1 allows remote attackers to execute arbitrary code via a crafted argument to the getIcon method of a Collab o…

8.8 CVSS
93.3% EPSS
CVE-2017-0146 🔴 Łataj teraz KEV

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 20…

8.8 CVSS
93.3% EPSS
siemensexploitrce 2017-03-17
CVE-2014-0322 🔴 Łataj teraz KEV
appscloud

Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code via vectors involving crafted JavaScript code, CMarkup, and the onpropertychange attribute of a scrip…

8.8 CVSS
93.2% EPSS
microsoftexploit 2014-02-14
CVE-2012-1889 🔴 Łataj teraz KEV
appscloud

Microsoft XML Core Services 3.0, 4.0, 5.0, and 6.0 accesses uninitialized memory locations, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.

8.8 CVSS
93.1% EPSS
microsoftdos 2012-06-13
CVE-2015-2051 🔴 Łataj teraz KEV
network

The D-Link DIR-645 Wired/Wireless Router Rev. Ax with firmware 1.04b12 and earlier allows remote attackers to execute arbitrary commands via a GetDeviceSettings action to the HNAP interface.

8.8 CVSS
93.0% EPSS
dlinkexploit 2015-02-23
CVE-2023-38831 🔴 Łataj teraz KEV

RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. The issue occurs because a ZIP archive may include a benign file (such as an ordinary …

7.8 CVSS
97.8% EPSS
rarlabexploit 2023-08-23
CVE-2022-30333 🔴 Łataj teraz KEV
os

RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_keys file. NOTE: WinRAR and Android RAR ar…

7.5 CVSS
99.1% EPSS
CVE-2023-36884 🔴 Łataj teraz KEV
appscloud

Windows Search Remote Code Execution Vulnerability

7.5 CVSS
98.9% EPSS
microsoftrce 2023-07-11
CVE-2023-0669 🔴 Łataj teraz KEV

Fortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due to deserializing an arbitrary attacker-controlled object. This issue was…

7.2 CVSS
100.0% EPSS
fortraexploitrce 2023-02-06
CVE-2016-3714 🔴 Łataj teraz KEV
os

The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to execute arbitrary code via shell metacharact…

8.4 CVSS
94.0% EPSS
canonical 2016-05-05
CVE-2024-21412 🔴 Łataj teraz KEV
appscloud

Internet Shortcut Files Security Feature Bypass Vulnerability

8.1 CVSS
95.4% EPSS
microsoft 2024-02-13
CVE-2015-2426 🔴 Łataj teraz KEV
appscloud

Buffer underflow in atmfd.dll in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Wind…

8.8 CVSS
91.8% EPSS
microsoftexploit 2015-07-20
CVE-2021-42321 🔴 Łataj teraz KEV
appscloud

Microsoft Exchange Server Remote Code Execution Vulnerability

8.8 CVSS
91.7% EPSS
microsoftexploitrce 2021-11-10
CVE-2012-1856 🔴 Łataj teraz KEV
appscloud

The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office 2003 SP3, Office 2003 Web Components SP3, Office 2007 SP2 and SP3, Office 2010 SP1, SQL Server 2000 SP4, SQL Server 2005 SP4, SQL Se…

8.8 CVSS
91.5% EPSS
microsoftrce 2012-08-15
CVE-2012-4792 🔴 Łataj teraz KEV
appscloud

Use-after-free vulnerability in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to an object that (1) was not properly allocated or (2…

8.8 CVSS
91.4% EPSS
microsoft 2012-12-30
CVE-2016-6366 🔴 Łataj teraz KEV
network

Buffer overflow in Cisco Adaptive Security Appliance (ASA) Software through 9.4.2.3 on ASA 5500, ASA 5500-X, ASA Services Module, ASA 1000V, ASAv, Firepower 9300 ASA Security Module, PIX, and FWSM devices allows remote a…

8.8 CVSS
91.4% EPSS
CVE-2025-61884 🔴 Łataj teraz KEV
appsos

Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attac…

7.5 CVSS
97.8% EPSS
oracleexploit 2025-10-12
CVE-2013-2551 🔴 Łataj teraz KEV
appscloud

Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, as demonstrated by VUPEN during …

8.8 CVSS
91.3% EPSS
microsoft 2013-03-11
CVE-2018-20250 🔴 Łataj teraz KEV

In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.dll). When the filename field is manipulated with specific patterns, th…

7.8 CVSS
96.3% EPSS
CVE-2009-3459 🔴 Łataj teraz KEV

Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption, as e…

8.8 CVSS
91.0% EPSS
CVE-2017-9805 🔴 Łataj teraz KEV
network

The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code …

8.1 CVSS
94.3% EPSS
CVE-2017-17562 🔴 Łataj teraz KEV
appsos

Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. This is a result of initializing the environment of forked CGI scripts using untrusted HTTP request p…

8.1 CVSS
94.3% EPSS
oracleexploitrce 2017-12-12
CVE-2021-26857 🔴 Łataj teraz KEV
appscloud

Microsoft Exchange Server Remote Code Execution Vulnerability

7.8 CVSS
95.8% EPSS
microsoftrce 2021-03-03
CVE-2021-33766 🔴 Łataj teraz KEV
appscloud

Microsoft Exchange Server Information Disclosure Vulnerability

7.3 CVSS
98.2% EPSS
microsoft 2021-07-14
CVE-2014-0502 🔴 Łataj teraz KEV
os

Double free vulnerability in Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac OS X and before 11.2.202.341 on Linux, Adobe AIR before 4.0.0.1628 on Android, Adobe AIR S…

8.8 CVSS
90.6% EPSS
redhatexploit 2014-02-21
CVE-2022-27925 🔴 Łataj teraz KEV

Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. An authenticated user with administrator rights has the ability to upload arbitrary files…

7.2 CVSS
98.6% EPSS
CVE-2017-0148 🔴 Łataj teraz KEV

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 20…

8.1 CVSS
94.1% EPSS
siemensexploitrce 2017-03-17
CVE-2009-3953 🔴 Łataj teraz KEV

The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x before 7.1.4 allows remote attackers to execute arbitrary code via malformed U3D data in a PDF document, …

8.8 CVSS
90.5% EPSS
adobe 2010-01-13
CVE-2017-5521 🔴 Łataj teraz KEV
network

An issue was discovered on NETGEAR R8500, R8300, R7000, R6400, R7300, R7100LG, R6300v2, WNDR3400v3, WNR3500Lv2, R6250, R6700, R6900, and R8000 devices. They are prone to password disclosure via simple crafted requests to…

8.1 CVSS
93.8% EPSS
netgearexploit 2017-01-17
CVE-2016-7201 🔴 Łataj teraz KEV
appscloud

The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption …

8.8 CVSS
90.1% EPSS
microsoftdosexploit 2016-11-10
CVE-2014-6278 🔴 Łataj teraz KEV

GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to execute arbitrary commands via a crafted environment, as demonstrated …

8.8 CVSS
90.1% EPSS
gnu 2014-09-30
CVE-2021-4034 🔴 Łataj teraz KEV
os

A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined polic…

7.8 CVSS
94.9% EPSS
CVE-2014-6324 🔴 Łataj teraz KEV
appscloud

The Kerberos Key Distribution Center (KDC) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows re…

8.8 CVSS
89.9% EPSS
microsoft 2014-11-18
CVE-2017-0145 🔴 Łataj teraz KEV

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 20…

8.8 CVSS
89.8% EPSS
siemensexploitrce 2017-03-17
CVE-2026-31431 🔴 Łataj teraz KEV

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is…

7.8 CVSS
94.5% EPSS
suseexploit 2026-04-22
CVE-2017-11882 🔴 Łataj teraz KEV
appscloud

Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Microsoft Office 2016 allow an attacker to run arbitrary code in the context of the current user by fa…

7.8 CVSS
94.4% EPSS
microsoftexploit 2017-11-15
CVE-2017-0199 🔴 Łataj teraz KEV
appscloud

Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Windows Vista SP2, Windows Server 2008 SP2, Windows 7 SP1, Windows 8.1 allow remote attackers to execute a…

7.8 CVSS
94.3% EPSS
microsoftexploitrce 2017-04-12
CVE-2017-8570 🔴 Łataj teraz KEV
appscloud

Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Microsoft Office Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-0243.

7.8 CVSS
94.3% EPSS
microsoftexploitrce 2017-07-11
CVE-2017-6334 🔴 Łataj teraz KEV
network

dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the host_name field of an HTTP POST request, a diffe…

8.8 CVSS
89.2% EPSS
netgearexploit 2017-03-06
CVE-2015-8651 🔴 Łataj teraz KEV

Integer overflow in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe A…

8.8 CVSS
89.1% EPSS
adobe 2015-12-28
CVE-2017-6736 🔴 Łataj teraz KEV
network

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an authenticated, remote attacker to remotely execute code on an affected system…

8.8 CVSS
89.0% EPSS
CVE-2017-8759 🔴 Łataj teraz KEV
appscloud

Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely via a malicious document or application, aka ".NET Framework Remote Code Execution Vulnerability."

7.8 CVSS
94.0% EPSS
microsoftexploitrce 2017-09-13
CVE-2010-3333 🔴 Łataj teraz KEV
appscloud

Stack-based buffer overflow in Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2010, Office 2004 and 2008 for Mac, Office for Mac 2011, and Open XML File Format Converter for Mac allows remote attackers…

7.8 CVSS
93.8% EPSS
CVE-2008-2992 🔴 Łataj teraz KEV

Stack-based buffer overflow in Adobe Acrobat and Reader 8.1.2 and earlier allows remote attackers to execute arbitrary code via a PDF file that calls the util.printf JavaScript function with a crafted format string argum…

7.8 CVSS
93.7% EPSS
CVE-2010-0249 🔴 Łataj teraz KEV
appscloud

Use-after-free vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 on Windows 2000 SP4; Windows XP SP2 and SP3; Windows Server 2003 SP2; Windows Vista Gold, SP1, and SP2; Windows Server 2008 Gold, SP2, and R2…

8.8 CVSS
88.7% EPSS
microsoftexploit 2010-01-15
CVE-2024-57727 🔴 Łataj teraz KEV

SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enable unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted …

7.5 CVSS
95.2% EPSS
CVE-2021-26858 🔴 Łataj teraz KEV
appscloud

Microsoft Exchange Server Remote Code Execution Vulnerability

7.8 CVSS
93.7% EPSS
microsoftrce 2021-03-03
CVE-2015-1641 🔴 Łataj teraz KEV
appscloud

Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word for Mac 2011, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP2 and 2013 SP1, and Office …

7.8 CVSS
93.6% EPSS
microsoft 2015-04-14
CVE-2015-2545 🔴 Łataj teraz KEV
appscloud

Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1, and 2013 RT SP1 allows remote attackers to execute arbitrary code via a crafted EPS image, aka "Microsoft Office Malformed EPS File Vulnerability."

7.8 CVSS
93.3% EPSS
microsoftexploit 2015-09-09
CVE-2014-1761 🔴 Łataj teraz KEV
appscloud

Microsoft Word 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Word Viewer; Office Compatibility Pack SP3; Office for Mac 2011; Word Automation Services on SharePoint Server 2010 SP1 and SP2 and 2013; Office Web…

7.8 CVSS
93.3% EPSS
microsoftdos 2014-03-25
CVE-2011-3402 🔴 Łataj teraz KEV
appscloud

Unspecified vulnerability in the TrueType font parsing engine in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 …

8.8 CVSS
88.3% EPSS
microsoft 2011-11-04
CVE-2012-4969 🔴 Łataj teraz KEV
appscloud

Use-after-free vulnerability in the CMshtmlEd::Exec function in mshtml.dll in Microsoft Internet Explorer 6 through 9 allows remote attackers to execute arbitrary code via a crafted web site, as exploited in the wild in …

8.1 CVSS
91.8% EPSS
microsoft 2012-09-18
CVE-2013-3897 🔴 Łataj teraz KEV
appscloud

Use-after-free vulnerability in the CDisplayPointer class in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via c…

8.8 CVSS
88.2% EPSS
microsoftdos 2013-10-09
CVE-2016-7200 🔴 Łataj teraz KEV
appscloud

The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption …

8.8 CVSS
88.1% EPSS
microsoftdosexploit 2016-11-10
CVE-2007-5659 🔴 Łataj teraz KEV

Multiple buffer overflows in Adobe Reader and Acrobat 8.1.1 and earlier allow remote attackers to execute arbitrary code via a PDF file with long arguments to unspecified JavaScript methods. NOTE: this issue might be su…

7.8 CVSS
93.1% EPSS
CVE-2012-0754 🔴 Łataj teraz KEV

Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.6 on Android 2.x and 3.x; and before 11.1.115.6 on Android 4.x allows attackers to execute arbit…

8.1 CVSS
91.5% EPSS
adobedos 2012-02-16
CVE-2014-0160 🔴 Łataj teraz KEV

The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted pa…

7.5 CVSS
94.5% EPSS
mitelexploit 2014-04-07
CVE-2017-8291 🔴 Łataj teraz KEV
os

Artifex Ghostscript through 2017-04-26 allows -dSAFER bypass and remote command execution via .rsdparams type confusion with a "/OutputFile (%pipe%" substring in a crafted .eps document that is an input to the gs program…

7.8 CVSS
92.9% EPSS
redhatexploit 2017-04-27
CVE-2009-4324 🔴 Łataj teraz KEV

Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code v…

7.8 CVSS
92.9% EPSS
adobeexploit 2009-12-15
CVE-2010-1297 🔴 Łataj teraz KEV

Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64; Adobe AIR before 2.0.2.12610; and Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow remote attackers to execute…

7.8 CVSS
92.8% EPSS
adobedosexploit 2010-06-08
CVE-2013-1347 🔴 Łataj teraz KEV
appscloud

Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly allocated or (2) is deleted, as exploited…

8.8 CVSS
87.7% EPSS
microsoftexploit 2013-05-05
CVE-2013-3906 🔴 Łataj teraz KEV
appscloud

GDI+ in Microsoft Windows Vista SP2 and Server 2008 SP2; Office 2003 SP3, 2007 SP3, and 2010 SP1 and SP2; Office Compatibility Pack SP3; and Lync 2010, 2010 Attendee, 2013, and Basic 2013 allows remote attackers to execu…

7.8 CVSS
92.6% EPSS
microsoftexploit 2013-11-06
CVE-2017-0261 🔴 Łataj teraz KEV
appscloud

Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016 allow a remote code execution vulnerability when the software fails to properly handle objects in memory, aka "Office Remote Code Execution Vulnerability". This…

7.8 CVSS
92.5% EPSS
microsoftrce 2017-05-12
CVE-2017-3506 🔴 Łataj teraz KEV
appsos

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0, 12.1.3.0, 12.2.1.0, 12.2.1.1 and 12.2.1.2. Difficult to e…

7.4 CVSS
94.4% EPSS
oracle 2017-04-24
CVE-2013-0640 🔴 Łataj teraz KEV
os

Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted PDF document, as expl…

7.8 CVSS
92.3% EPSS
redhatdos 2013-02-14
CVE-2020-5849 🔴 Łataj teraz KEV

Unraid 6.8.0 allows authentication bypass.

7.5 CVSS
93.8% EPSS
CVE-2010-0806 🔴 Łataj teraz KEV
appscloud

Use-after-free vulnerability in the Peer Objects component (aka iepeers.dll) in Microsoft Internet Explorer 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via vectors involving access to an invalid poi…

8.8 CVSS
87.3% EPSS
microsoft 2010-03-10
CVE-2010-2568 🔴 Łataj teraz KEV
appscloud

Windows Shell in Microsoft Windows XP SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 SP2 and R2, and Windows 7 allows local users or remote attackers to execute arbitrary code via a crafted (1) .LNK or (2) .PIF sho…

7.8 CVSS
92.1% EPSS
microsoftexploit 2010-07-22
CVE-2014-4114 🔴 Łataj teraz KEV
appscloud

Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote attackers to execute arbitrary code via a …

7.8 CVSS
92.1% EPSS
microsoftexploitrce 2014-10-15
CVE-2015-0016 🔴 Łataj teraz KEV
appscloud

Directory traversal vulnerability in the TS WebProxy (aka TSWbPrxy) component in Microsoft Windows Vista SP2, Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Window…

CVE-2011-0609 🔴 Łataj teraz KEV

Unspecified vulnerability in Adobe Flash Player 10.2.154.13 and earlier on Windows, Mac OS X, Linux, and Solaris; 10.1.106.16 and earlier on Android; Adobe AIR 2.5.1 and earlier; and Authplay.dll (aka AuthPlayLib.bundle)…

7.8 CVSS
92.1% EPSS
adobedos 2011-03-15
CVE-2017-0037 🔴 Łataj teraz KEV
appscloud

Microsoft Internet Explorer 10 and 11 and Microsoft Edge have a type confusion issue in the Layout::MultiColumnBoxBuilder::HandleColumnBreakOnColumnSpanningElement function in mshtml.dll, which allows remote attackers to…

8.1 CVSS
90.5% EPSS
microsoftexploit 2017-02-26
CVE-2013-3918 🔴 Łataj teraz KEV
appscloud

The InformationCardSigninHelper Class ActiveX control in icardie.dll in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows …

8.8 CVSS
87.0% EPSS
microsoftdos 2013-11-12
CVE-2017-12637 🔴 Łataj teraz KEV

Directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS in SAP NetWeaver Application Server Java 7.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the query string…

7.5 CVSS
93.5% EPSS
sappath-traversal 2017-08-07
CVE-2024-9474 🔴 Łataj teraz KEV
network

A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firewall with root privileges. Cloud NGFW an…

7.2 CVSS
94.8% EPSS
CVE-2015-3035 🔴 Łataj teraz KEV
network

Directory traversal vulnerability in TP-LINK Archer C5 (1.2) with firmware before 150317, C7 (2.0) with firmware before 150304, and C8 (1.0) with firmware before 150316, Archer C9 (1.0), TL-WDR3500 (1.0), TL-WDR3600 (1.0…

7.5 CVSS
93.1% EPSS
CVE-2012-1535 🔴 Łataj teraz KEV
os

Unspecified vulnerability in Adobe Flash Player before 11.3.300.271 on Windows and Mac OS X and before 11.2.202.238 on Linux allows remote attackers to execute arbitrary code or cause a denial of service (application cra…

7.8 CVSS
91.6% EPSS
redhatdos 2012-08-15
CVE-2016-6415 🔴 Łataj teraz KEV
network

The server IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.6, IOS XE through 3.18S, IOS XR 4.3.x and 5.0.x through 5.2.x, and PIX before 7.0 allows remote attackers to obtain sensitive information…

7.5 CVSS
93.0% EPSS
cisco 2016-09-19
CVE-2009-3129 🔴 Łataj teraz KEV
appscloud

Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer 2003 SP3; Office Excel Viewer SP1 and SP2; and Office Compatibili…

7.8 CVSS
91.2% EPSS
microsoftexploit 2009-11-11
CVE-2017-0147 🔴 Łataj teraz KEV

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 20…

7.5 CVSS
92.4% EPSS
siemensexploit 2017-03-17
CVE-2017-11826 🔴 Łataj teraz KEV
appscloud

Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Server 2010 and 2013, Word Viewer, Word 2007, 2010, 2013 and 2016, Word Automation Services, and Office …

7.8 CVSS
90.8% EPSS
microsoftexploitrce 2017-10-13
CVE-2014-6352 🔴 Łataj teraz KEV
appscloud

Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote attackers to execute arbitrary code via a …

7.8 CVSS
90.7% EPSS
microsoft 2014-10-22
CVE-2010-2883 🔴 Łataj teraz KEV

Stack-based buffer overflow in CoolType.dll in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows remote attackers to execute arbitrary code or cause a denial of service (applic…

7.3 CVSS
93.2% EPSS
CVE-2016-0099 🔴 Łataj teraz KEV
appscloud

The Secondary Logon Service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 does not properly …

7.8 CVSS
90.4% EPSS
CVE-2010-3962 🔴 Łataj teraz KEV
appscloud

Use-after-free vulnerability in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary code via vectors related to Cascading Style Sheets (CSS) token sequences and the clip attribute, aka an…

8.1 CVSS
88.9% EPSS
microsoft 2010-11-05
CVE-2017-0213 🔴 Łataj teraz KEV
appscloud

Windows COM Aggregate Marshaler in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016…

7.3 CVSS
92.7% EPSS
CVE-2016-5195 🔴 Łataj teraz KEV
os

Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature to write to a read-only memory mapping, …

7.0 CVSS
94.2% EPSS
redhatexploit 2016-11-10
CVE-2013-3163 🔴 Łataj teraz KEV
appscloud

Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability,"…

8.8 CVSS
84.5% EPSS
microsoftdos 2013-07-10
CVE-2016-0752 🔴 Łataj teraz KEV

Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 allows remote attackers to read arbitrary files by le…

7.5 CVSS
91.0% EPSS
CVE-2024-27199 🔴 Łataj teraz KEV

In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible

7.3 CVSS
92.0% EPSS
CVE-2016-7255 🔴 Łataj teraz KEV
appscloud

The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server…

7.8 CVSS
89.4% EPSS
CVE-2016-0189 🔴 Łataj teraz KEV
appscloud

The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corr…

7.5 CVSS
90.8% EPSS
microsoftdosexploit 2016-05-11
CVE-2012-0151 🔴 Łataj teraz KEV
appscloud

The Authenticode Signature Verification function in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and Windows 8 Consumer Pr…

7.8 CVSS
89.0% EPSS
microsoft 2012-04-10
CVE-2013-1331 🔴 Łataj teraz KEV
appscloud

Buffer overflow in Microsoft Office 2003 SP3 and Office 2011 for Mac allows remote attackers to execute arbitrary code via crafted PNG data in an Office document, leading to improper memory allocation, aka "Office Buffer…

7.8 CVSS
88.9% EPSS
CVE-2010-0188 🔴 Łataj teraz KEV

Unspecified vulnerability in Adobe Reader and Acrobat 8.x before 8.2.1 and 9.x before 9.3.1 allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors.

7.8 CVSS
88.3% EPSS
adobedos 2010-02-22
CVE-2024-21182 🔴 Łataj teraz KEV
appsos

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthentic…

7.5 CVSS
89.6% EPSS
oracle 2024-07-16
CVE-2014-1812 🔴 Łataj teraz KEV
appscloud

The Group Policy implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 does not properly handle distribution of pass…

8.8 CVSS
83.1% EPSS
CVE-2013-0641 🔴 Łataj teraz KEV
os

Buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allows remote attackers to execute arbitrary code via a crafted PDF document, as exploited in the wild in February…

7.8 CVSS
88.0% EPSS
CVE-2024-7399 🔴 Łataj teraz KEV

Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1050 allows attackers to write arbitrary file as system authority.

8.8 CVSS
82.3% EPSS
samsung 2024-08-12
CVE-2016-7262 🔴 Łataj teraz KEV
appscloud

Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, and Excel Viewer allow user-assisted remote attackers to execute arbitrary commands via a crafted ce…

7.8 CVSS
87.1% EPSS
microsoft 2016-12-20
CVE-2018-8174 🔴 Łataj teraz KEV
appscloud

A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R…

7.5 CVSS
88.5% EPSS
microsoftexploitrce 2018-05-09
CVE-2008-0015 🔴 Łataj teraz KEV
appscloud

Stack-based buffer overflow in the CComVariant::ReadFromStream function in the Active Template Library (ATL), as used in the MPEG2TuneRequest ActiveX control in msvidctl.dll in DirectShow, in Microsoft Windows 2000 SP4, …

8.8 CVSS
81.6% EPSS
CVE-2009-0557 🔴 Łataj teraz KEV
appscloud

Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac; Excel in 2007 Microsoft Office System SP1 and SP2; Open XML File Format Converter for Mac; Microsoft Office Excel View…

7.8 CVSS
86.4% EPSS
microsoft 2009-06-10
CVE-2013-3893 🔴 Łataj teraz KEV
appscloud

Use-after-free vulnerability in the SetMouseCapture implementation in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code via crafted JavaScript strings, as demonstrat…

8.8 CVSS
81.2% EPSS
microsoftexploit 2013-09-18
CVE-2009-0238 🔴 Łataj teraz KEV
appscloud

Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1; Excel Viewer 2003 Gold and SP3; Excel Viewer; Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1; and Excel in Microsoft Office 200…

8.8 CVSS
81.1% EPSS
microsoft 2009-02-25
CVE-2015-1671 🔴 Łataj teraz KEV
appscloud

The Windows DirectWrite library, as used in Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2; Office 2007 SP3 and 2010 SP2; Live Meeting 2007 Console; Lync 2010; Lync 2010 Attendee; Lync 2013 SP1; L…

7.8 CVSS
85.9% EPSS
microsoft 2015-05-13
CVE-2021-26411 🔴 Łataj teraz KEV
appscloud

Internet Explorer Memory Corruption Vulnerability

8.8 CVSS
80.8% EPSS
microsoft 2021-03-11
CVE-2026-42271 🔴 Łataj teraz KEV
os

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to before version 1.83.7, two endpoints used to preview an MCP server before saving it — POST /mcp-rest/test/conne…

8.8 CVSS
80.2% EPSS
redhat 2026-05-08
CVE-2021-23758 🔴 Łataj teraz KEV

All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET classes, which can be abused to gain remote code execution.

8.1 CVSS
83.6% EPSS
CVE-2021-1675 🔴 Łataj teraz KEV
appscloud

Windows Print Spooler Remote Code Execution Vulnerability

7.8 CVSS
84.8% EPSS
microsoftexploitrce 2021-06-08
CVE-2017-11774 🔴 Łataj teraz KEV
appscloud

Microsoft Outlook 2010 SP2, Outlook 2013 SP1 and RT SP1, and Outlook 2016 allow an attacker to execute arbitrary commands, due to how Microsoft Office handles objects in memory, aka "Microsoft Outlook Security Feature By…

7.8 CVSS
84.6% EPSS
microsoftexploit 2017-10-13
CVE-2017-8540 🔴 Łataj teraz KEV
appscloud

The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, …

7.8 CVSS
84.6% EPSS
microsoftexploitrce 2017-05-26
CVE-2023-27351 🔴 Łataj teraz KEV

This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability. The specific flaw exists wi…

7.5 CVSS
86.1% EPSS
papercutauth-bypass 2023-04-20
CVE-2015-7645 🔴 Łataj teraz KEV
os

Adobe Flash Player 18.x through 18.0.0.252 and 19.x through 19.0.0.207 on Windows and OS X and 11.x through 11.2.202.535 on Linux allows remote attackers to execute arbitrary code via a crafted SWF file, as exploited in …

7.8 CVSS
84.5% EPSS
redhat 2015-10-15
CVE-2012-2539 🔴 Łataj teraz KEV
appscloud

Microsoft Word 2003 SP3, 2007 SP2 and SP3, and 2010 SP1; Word Viewer; Office Compatibility Pack SP2 and SP3; and Office Web Apps 2010 SP1 allow remote attackers to execute arbitrary code or cause a denial of service (mem…

7.8 CVSS
84.4% EPSS
microsoftdosrce 2012-12-12
CVE-2023-41266 🔴 Łataj teraz KEV

A path traversal vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and August 2022 Patch 12 and ear…

8.2 CVSS
82.1% EPSS
qlikpath-traversal 2023-08-29
CVE-2014-3120 🔴 Łataj teraz KEV
apps

The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code via the source parameter to _search. NOTE: this only vio…

8.1 CVSS
82.6% EPSS
elasticexploit 2014-07-28
CVE-2022-27924 🔴 Łataj teraz KEV

Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 allows an unauthenticated attacker to inject arbitrary memcache commands into a targeted instance. These memcache commands becomes unescaped, causing an overwrite of arbitrar…

7.5 CVSS
85.4% EPSS
synacor 2022-04-21
CVE-2025-34291 🔴 Łataj teraz KEV

Langflow versions up to and including 1.6.9 contain a chained vulnerability that enables account takeover and remote code execution. An overly permissive CORS configuration (allow_origins='*' with allow_credentials=True)…

8.8 CVSS
78.9% EPSS
langflowexploitrce 2025-12-05
CVE-2016-5198 🔴 Łataj teraz KEV
cloud

V8 in Google Chrome prior to 54.0.2840.90 for Linux, and 54.0.2840.85 for Android, and 54.0.2840.87 for Windows and Mac included incorrect optimisation assumptions, which allowed a remote attacker to perform arbitrary re…

8.8 CVSS
78.7% EPSS
googleexploit 2017-01-19
CVE-2023-38950 🔴 Łataj teraz KEV

A path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read arbitrary files via supplying a crafted payload. This vulnerability was fixed in version 9.0.120240617.19…

7.5 CVSS
84.9% EPSS
CVE-2016-4657 🔴 Łataj teraz KEV
os

WebKit in Apple iOS before 9.3.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.

8.8 CVSS
78.3% EPSS
appledosexploit 2016-08-25
CVE-2015-1770 🔴 Łataj teraz KEV
appscloud

Microsoft Office 2013 SP1 and 2013 RT SP1 allows remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Uninitialized Memory Use Vulnerability."

8.8 CVSS
78.2% EPSS
microsoft 2015-06-10
CVE-2016-0185 🔴 Łataj teraz KEV
appscloud

Media Center in Microsoft Windows Vista SP2, Windows 7 SP1, and Windows 8.1 allows remote attackers to execute arbitrary code via a crafted Media Center link (aka .mcl) file, aka "Windows Media Center Remote Code Executi…

7.8 CVSS
82.8% EPSS
microsoftrce 2016-05-11
CVE-2018-15982 🔴 Łataj teraz KEV

Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

7.8 CVSS
82.5% EPSS
adobeexploitrce 2019-01-18
CVE-2014-4113 🔴 Łataj teraz KEV
appscloud

win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Go…

7.8 CVSS
82.4% EPSS
CVE-2022-41080 🔴 Łataj teraz KEV
appscloud

Microsoft Exchange Server Elevation of Privilege Vulnerability

8.8 CVSS
77.3% EPSS
CVE-2013-0074 🔴 Łataj teraz KEV
appscloud

Microsoft Silverlight 5, and 5 Developer Runtime, before 5.1.20125.0 does not properly validate pointers during HTML object rendering, which allows remote attackers to execute arbitrary code via a crafted Silverlight app…

7.8 CVSS
81.9% EPSS
microsoft 2013-03-13
CVE-2017-6327 🔴 Łataj teraz KEV

The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of remote code execution, which describes a situation whereby an individual may obtain the ability to execute commands remotely on a target machine …

8.8 CVSS
76.8% EPSS
symantecrce 2017-08-11
CVE-2016-3235 🔴 Łataj teraz KEV
appscloud

Microsoft Visio 2007 SP3, Visio 2010 SP2, Visio 2013 SP1, Visio 2016, Visio Viewer 2007 SP3, and Visio Viewer 2010 mishandle library loading, which allows local users to gain privileges via a crafted application, aka "Mi…

7.8 CVSS
81.6% EPSS
microsoftexploit 2016-06-16
CVE-2015-2424 🔴 Łataj teraz KEV
appscloud

Microsoft PowerPoint 2007 SP3, Word 2007 SP3, PowerPoint 2010 SP2, Word 2010 SP2, PowerPoint 2013 SP1, Word 2013 SP1, and PowerPoint 2013 RT SP1 allow remote attackers to execute arbitrary code or cause a denial of servi…

8.8 CVSS
76.5% EPSS
microsoftdos 2015-07-14
CVE-2009-0556 🔴 Łataj teraz KEV
appscloud

Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3, and PowerPoint in Microsoft Office 2004 for Mac, allows remote attackers to execute arbitrary code via a PowerPoint file with an OutlineTextRefAtom containing…

8.8 CVSS
76.4% EPSS
microsoft 2009-04-03
CVE-2026-34486 🔴 Łataj teraz KEV
os

Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users ar…

7.5 CVSS
82.9% EPSS
redhat 2026-04-09
CVE-2025-64328 🔴 Łataj teraz KEV

FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. In versions 17.0.2.36 and above before 17.0.3, the filestore module within the Administrative interface is vulnerable to a post-au…

7.2 CVSS
84.0% EPSS
sangomaexploitrce 2025-11-07
CVE-2016-0984 🔴 Łataj teraz KEV

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260,…

8.8 CVSS
75.9% EPSS
adobeexploit 2016-02-10
CVE-2013-0629 🔴 Łataj teraz KEV

Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10, when a password is not configured, allows attackers to access restricted directories via unspecified vectors, as exploited in the wild in January 2013.

7.5 CVSS
81.8% EPSS
adobe 2013-01-09
CVE-2021-25298 🔴 Łataj teraz KEV

Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/cloud-vm/cloud-vm.inc.php due to improper sanitization of authenticated…

8.8 CVSS
75.2% EPSS
nagiosexploitrce 2021-02-15
CVE-2013-0631 🔴 Łataj teraz KEV

Adobe ColdFusion 9.0, 9.0.1, and 9.0.2 allows attackers to obtain sensitive information via unspecified vectors, as exploited in the wild in January 2013.

7.5 CVSS
81.6% EPSS
adobe 2013-01-09
CVE-2019-0752 🔴 Łataj teraz KEV
appscloud

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-201…

7.5 CVSS
81.5% EPSS
microsoftexploitrce 2019-04-09
CVE-2009-0563 🔴 Łataj teraz KEV
appscloud

Stack-based buffer overflow in Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Microsoft Office for Mac 2004 and 2008; Open XML File Format Converter for Mac; Microsoft Office Word Viewer 2003 SP3; Micros…

7.8 CVSS
79.9% EPSS
CVE-2017-5070 🔴 Łataj teraz KEV
cloud

Type confusion in V8 in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac, and 59.0.3071.92 for Android, allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.

8.8 CVSS
74.4% EPSS
googleexploit 2017-10-27
CVE-2006-2492 🔴 Łataj teraz KEV
appscloud

Buffer overflow in Microsoft Word in Office 2000 SP3, Office XP SP3, Office 2003 Sp1 and SP2, and Microsoft Works Suites through 2006, allows user-assisted attackers to execute arbitrary code via a malformed object point…

8.8 CVSS
74.1% EPSS
CVE-2016-0040 🔴 Łataj teraz KEV
appscloud

The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows local users to gain privileges via a crafted application, aka "Windows Elevation of Privilege Vulnerability."

7.8 CVSS
78.9% EPSS
CVE-2021-1732 🔴 Łataj teraz KEV
appscloud

Windows Win32k Elevation of Privilege Vulnerability

7.8 CVSS
77.8% EPSS
CVE-2020-9715 🔴 Łataj teraz KEV

Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have an use-after-free vulnerability. Successful exploitation could lead to arbitra…

7.8 CVSS
77.7% EPSS
adobeexploitrce 2020-08-19
CVE-2012-5054 🔴 Łataj teraz KEV

Integer overflow in the copyRawDataTo method in the Matrix3D class in Adobe Flash Player before 11.4.402.265 allows remote attackers to execute arbitrary code via malformed arguments.

8.8 CVSS
72.1% EPSS
adobeexploit 2012-09-24
CVE-2021-21975 🔴 Łataj teraz KEV
cloud

Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forger…

7.5 CVSS
78.3% EPSS
vmwareexploitssrf 2021-03-31
CVE-2015-4495 🔴 Łataj teraz KEV
os

The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass the Same Origin Policy, and read arbitrary files or gain privileges, via vector…

8.8 CVSS
71.6% EPSS
redhatexploit 2015-08-08
CVE-2021-25296 🔴 Łataj teraz KEV

Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/windowswmi/windowswmi.inc.php due to improper sanitization of authentic…

8.8 CVSS
71.5% EPSS
nagiosexploitrce 2021-02-15
CVE-2008-0655 🔴 Łataj teraz KEV

Multiple unspecified vulnerabilities in Adobe Reader and Acrobat before 8.1.2 have unknown impact and attack vectors.

8.8 CVSS
70.9% EPSS
adobeexploit 2008-02-07
CVE-2022-2294 🔴 Łataj teraz KEV
os

Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

8.8 CVSS
70.5% EPSS
CVE-2016-3976 🔴 Łataj teraz KEV

Directory traversal vulnerability in SAP NetWeaver AS Java 7.1 through 7.5 allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in the fileName parameter to CrashFileDownloadServlet, aka SAP Secu…

7.5 CVSS
76.3% EPSS
CVE-2010-2572 🔴 Łataj teraz KEV
appscloud

Buffer overflow in Microsoft PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint 95 document, aka "PowerPoint Parsing Buffer Overflow Vulnerability."

7.8 CVSS
74.7% EPSS
CVE-2024-20353 🔴 Łataj teraz KEV
network

A vulnerability in the management and VPN web servers for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the de…

8.6 CVSS
70.7% EPSS
ciscodosexploit 2024-04-24
CVE-2015-2419 🔴 Łataj teraz KEV
appscloud

JScript 9 in Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "JScript9 Memory Corruption Vulnerability.…

8.8 CVSS
69.4% EPSS
microsoftdos 2015-07-14
CVE-2021-42287 🔴 Łataj teraz KEV
appscloud

Active Directory Domain Services Elevation of Privilege Vulnerability

7.5 CVSS
75.8% EPSS
CVE-2019-1458 🔴 Łataj teraz KEV
appscloud

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'.

7.8 CVSS
73.9% EPSS
CVE-2015-1642 🔴 Łataj teraz KEV
appscloud

Microsoft Office 2007 SP3, 2010 SP2, and 2013 SP1 allows remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability."

7.8 CVSS
72.9% EPSS
microsoft 2015-08-15
CVE-2013-6282 🔴 Łataj teraz KEV
os

The (1) get_user and (2) put_user API functions in the Linux kernel before 3.5.5 on the v6k and v7 ARM platforms do not validate certain addresses, which allows attackers to read or modify the contents of arbitrary kerne…

8.8 CVSS
67.7% EPSS
linuxexploit 2013-11-20
CVE-2010-0232 🔴 Łataj teraz KEV
appscloud

The kernel in Microsoft Windows NT 3.1 through Windows 7, including Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, and Windows Server 2008 Gold and SP2, when access t…

7.8 CVSS
72.6% EPSS
microsoftdosexploit 2010-01-21
CVE-2026-21509 🔴 Łataj teraz KEV
appscloud

Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.

7.8 CVSS
72.2% EPSS
microsoft 2026-01-26
CVE-2016-1646 🔴 Łataj teraz KEV
os

The Array.prototype.concat implementation in builtins.cc in Google V8, as used in Google Chrome before 49.0.2623.108, does not properly consider element data types, which allows remote attackers to cause a denial of serv…

8.8 CVSS
66.9% EPSS
redhatdosexploit 2016-03-29
CVE-2007-0671 🔴 Łataj teraz KEV
appscloud

Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allows remote user-assisted attackers to execute arbitrary code via unknown attack vectors, as demonstrat…

8.8 CVSS
66.8% EPSS
microsoft 2007-02-03
CVE-2023-4911 🔴 Łataj teraz KEV
os

A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES env…

7.8 CVSS
71.5% EPSS
CVE-2014-0496 🔴 Łataj teraz KEV

Use-after-free vulnerability in Adobe Reader and Acrobat 10.x before 10.1.9 and 11.x before 11.0.06 on Windows and Mac OS X allows attackers to execute arbitrary code via unspecified vectors.

8.8 CVSS
66.3% EPSS
adobe 2014-01-15
CVE-2016-7193 🔴 Łataj teraz KEV
appscloud

Microsoft Word 2007 SP2, Office 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibility Pack SP3, Word Viewer, Word Automation Services on SharePoint Server 2010 S…

7.8 CVSS
71.2% EPSS
microsoft 2016-10-14
CVE-2021-42278 🔴 Łataj teraz KEV
appscloud

Active Directory Domain Services Elevation of Privilege Vulnerability

7.5 CVSS
72.0% EPSS
CVE-2025-27363 🔴 Łataj teraz KEV
os

An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when attempting to parse font subglyph structures related to TrueType GX and variable font files. The vu…

8.1 CVSS
68.7% EPSS
debianrce 2025-03-11
CVE-2018-8453 🔴 Łataj teraz KEV
appscloud

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 20…

7.8 CVSS
70.0% EPSS
CVE-2016-7256 🔴 Łataj teraz KEV
appscloud

atmfd.dll in the Windows font library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and …

8.8 CVSS
64.7% EPSS
microsoftrce 2016-11-10
CVE-2018-8120 🔴 Łataj teraz KEV
appscloud

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows Server 2008, Windows…

7.0 CVSS
73.7% EPSS
CVE-2013-0643 🔴 Łataj teraz KEV
os

The Firefox sandbox in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171 on Windows and Mac OS X, and before 10.3.183.67 and 11.x before 11.2.202.273 on Linux, does not properly restrict privileges, whic…

8.8 CVSS
64.2% EPSS
redhat 2013-02-27
CVE-2013-3660 🔴 Łataj teraz KEV
appscloud

The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8,…

7.8 CVSS
69.2% EPSS
microsoftexploit 2013-05-24